Getting Data In

How to remove an indexer from the distributed management console?

a212830
Champion

Hi,

I removed some indexers from Splunk, using the offline command, but they are all still showing up in my distributed management console, and listed as "unreachable". How do I remove them from the DMC?

lgely
Explorer

Hi,

modify the assets.csv file on the instance where is installed DMC

file locate = etc/apps/splunk_management_console/lookups/assets.csv

You need to update this file with the new/good informations (in my case new SH, change name/IP and ID if different)

I just :
modify my "distsearch.conf" on DMC instance
modify the "assets.csv" on DMC instance
add the trusted.pem on my new SH
restart my new SH and my DMC instance
and all is OK

Hope help you

sherm77
Path Finder

This was the only thing that worked for me, at least editing the assets.csv. A decomm'd indexer wouldn't go away from the monitoring console, editing the assets.csv took the indexer out of the monitoring console (v6.6.3).

0 Karma

xtrjx
Explorer

I also had the same problem but the indexer I took down did not show at all in the DMC settings so I could not disable it. I just clicked the "Apply Changes" button anyway and that removed the indexer from the other DMC views.

DEAD_BEEF
Builder

Go to Settings > Monitoring Console > Settings > General Setup > "Apply Changes"

For some reason this fixed my issue as well despite making no other changes.

isoutamo
SplunkTrust
SplunkTrust
This will update those lookups which are used for MC’s different views. It is always needed after you have done those changes on your infrastructure.
0 Karma

Gregski11
Contributor

this worked for us, after days of struggle, thank you so much

0 Karma

greich
Communicator

whether you edit in UI or the conf files, it does not always update the kvstore until you "Apply changes"

0 Karma

amiller100
New Member

I had to do the same as above. Within the Monitoring Console I performed the "Apply Changes" and that removed the decommissioned indexer from view.

0 Karma

CaptainHook
Communicator

After you click on "Apply Changes" that did work for me also.

0 Karma

fabiocaldas
Contributor

I had the same problem but runnign all steps again it worked

1 - Open the DMC -> Settings -> General Setup -> Edit next to the indexer -> Disable monitoring
2 - Restart Master server
3 - Apply Changes on DMC -> Settings -> General Setup

fabiocaldas
Contributor

I did what @somesoni2 and @jkat54 recommended but node is still "Unreachable"

0 Karma

mosman_splunk
Splunk Employee
Splunk Employee

you need to disable it as search peer Settings / Distributed search / Search peers

then you need to remove it from dmc settings" -> general setup -> edit next to the indexer -> disable monitoring

0 Karma

a212830
Champion

See above - did all that...

0 Karma

fabiocaldas
Contributor

I also did but it doesn't solved the problem

0 Karma

jkat54
SplunkTrust
SplunkTrust

See if this works:

Open the DMC, click on menu called "settings" -> general setup -> edit next to the indexer -> disable monitoring

0 Karma

a212830
Champion

It gets more interesting...

The "Overview" page shows 18 indexers and 12 unreachable (the 12 that I decommed via "offline"). The general setup page does not show them at all. I went into the "managementconsole_overview" view, and it lists the following:

<?xml version="1.0"?>
<view template="pages/app.html" type="html">
    <label>Overview</label>
</view>

I looked for that html page under ../etc, but found nothing. Thoughts?

0 Karma

somesoni2
Revered Legend

You can just remove them from Settings / Distributed search / Search peers

0 Karma

a212830
Champion

Did that, restarted DMC - didn't make a difference.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...